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DETAILED ACTION 
Continued Examination Under 37 CFR LI 14 

1 . A request for continued examination under 37 CFR 1.114, including the fee set forth in 
37 CFR 1 .17(e), was filed in this application after final rejection. Since this appHcation is 
eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) 
has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 
37 CFR 1.114. Applicant's submission filed on 27 December 2004 has been entered. 

2. Claims 1, 3, 6, 8, 9, 11, 13-16, 18, 20-23, 25, 27, 29 and 31-38 have been presented for 
examination. 

3. Claims 2, 4, 5, 7, 10, 12, 17, 19, 24, 26, 28 and 30 have been cancelled as per Applicant's 
request. 

Response to Arguments 

4. Applicant's arguments filed 27 December 2004 have been fijUy considered but they are 
not persuasive. 

5. In response to Applicant's argument that the Examiner overlooked the feature that the 
candidate function generating means, the Examiner disagrees. Page 19 of the specification 
discloses that the candidate function generating means is an S-box (Figure 2, block 20, line 7). 
The cited sections of Kim disclose an S-box as candidate function generating means. Therefore, 
Kim teaches the candidate function generating means as claimed by the Applicant. 

6. Applicant's arguments fail to comply with 37 CFR 1 . 1 1 1(b) because they amount to a 
general allegation that the claims define a patentable invention without specifically pointing out 
how the language of the claims patentably distinguishes them from the references. 
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7. Applicant's arguments do not comply with 37 CFR 1 . 1 1 1(c) because they do not clearly 
point out the patentable novelty which he or she thinks the claims present in view of the state of 
the art disclosed by the references cited or the objections made. Further, they do not show how 
the amendments avoid such references or objections. 

8. In response to applicant's arguments against the references individually, one cannot show 
nonobviousness by attacking references individually where the rejections are based on 
combinations of references, In re Keller, 642F.2d413, 208 USPQ 871 (CCPA 1981); /« re 
Merck c& Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). 

9. See further rejections that follow. 

Claim Rejections - 35 USC § 102 

10. The text of those sections of Title 35, U.S. Code not included in this action can be found 
in a prior Office action. 

11. Claim 6 is rejected under 35 U.S.C. 102(b) as being anticipated by U.S. Patent No. 
5,796,837 to Kim et al., hereinafter Kim. 

12. As per claim 6, Kim teaches a random function generating apparatus for a data 
encryption device comprising: 

input means for inputting digital signals representing parameter values of each of a 
plurality of functions of different algebraic structures and storing them in storage means (Figures 
6 [blocks 602, 603, 604], 7 [blocks 702, 703], 8 [blocks 802, 803], 9 [blocks 902, 903], 10a 
[blocks 1002, 1003, 1004, 1005, 1006], 10b [blocks 1019, 1020, 1021, 1022], 11 [block 1102, 
1 103], 12 [block 1202, 1203]; column 1, lines 35-42; column 4, lines 1-9; column 4, lines 12-28; 
column 4, lines 41-63); 
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candidate function generating means for generating candidate functions each formed by a 
combination of said plurality of functions of different algebraic structures based on said plurality 
of parameters read out of storage means (Figures 6 [blocks 602, 603, 604], 7 [blocks 702, 703], 8 
[blocks 802, 803], 9 [blocks 902, 903], 10a [blocks 1002, 1003, 1004, 1005, 1006], 10b [blocks 
1019, 1020, 1021, 1022], 11 [block 1102, 1103], 12 [block 1202, 1203]; column 1, lines 35-42; 
column 4, lines 1-9; column 4, lines 12-28; column 4, lines 41-63); 

resistance evaluating means for evaluating the resistance of each of said candidate 
functions to a cryptanalysis (Figures 6 [blocks 606, 607], 7 [block 704], 8 [block 804], 9 [blocks 
904, 905], 10a [blocks 1007, 1008, 1009, 1010, 1011, 1012, 1013, 1014], 10b [blocks 1023, 
1024, 1025, 1026, 1027, 1028, 1029, 1030], 11 [block 1105], 12 [blocks 1205], 13a [blocks 
1305, 1306, 1307, 1308], 13b [blocks 1309, 1310, 1311]; column 4, lines 12-18; column 4, lines 
31-62; column 5, lines 1-40; column 5, hne 41 to column 6, line 13); and 

selecting means for selecting those of said resistance-evaluated candidate functions which 
are highly resistant to said cryptanalysis and outputting digital signals representing selected ones 
of said resistance-evaluated candidate functions (Figures 6 [blocks 606, 607], 7 [block 704], 8 
[block 804], 9 [blocks 904, 905], 10a [blocks 1007, 1008, 1009, 1010, 1011, 1012, 1013, 1014], 
10b [blocks 1023, 1024, 1025, 1026, 1027, 1028, 1029, 1030], 11 [block 1105], 12 [blocks 
1205], 13a [blocks 1305, 1306, 1307, 1308], 13b [blocks 1309, 1310, 1311]; column 4, lines 12- 
18; column 4, lines 31-62; column 5, lines 1-40; column 5, line 41 to column 6, line 13); 

wherein one of said plurality of fiinctions of different algebraic structures is resistant to 
each of differential cryptanalysis and linear cryptanalysis (column 4, lines 12-62). 
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Claim Rejections - 35 USC § 103 

13. The text of those sections of Title 35, U.S. Code not included in this action can be found 
in a prior Office action. 

14. Claims 1-3, 9-1 1, and 27-29 are rejected under 35 U.S.C. 103(a) as being unpatentable 
over Kim, in view of Differential-Linear Cryptanalysis to Susan K. Langford et al., hereinafter 
Langford. 

15. As per claims 1, 9, and 27, Kim teaches a function randomness evaluating apparatus for a 
data encryption device comprising: 

input means for inputting digital signals representing candidate functions S(x) of S-box to 
be evaluated, input difference value Dx and output mask values Dy, and storing them in storage 
means (Figures 6 [blocks 602, 603, 604], 7 [blocks 702, 703], 8 [blocks 802, 803], 9 [blocks 902, 
903], 10a [blocks 1002, 1003, 1004, 1005, 1006], 10b [blocks 1019, 1020, 1021, 1022], 11 
[block 1102, 1 103], 12 [block 1202, 1203]; column 1, lines 35-42; column 4, lines 1-9; column 
4, lines 12-28; column 4, lines 41-63); 

evaluating the resistance of said function to cryptanalysis based on the result of said 
number (Figures 6 [blocks 606, 607], 7 [block 704], 8 [block 804], 9 [blocks 904, 905], 10a 
[blocks 1007, 1008, 1009, 1010, 1011, 1012, 1013, 1014], 10b [blocks 1023, 1024, 1025, 1026, 
1027, 1028, 1029, 1030], 11 [block 1105], 12 [blocks 1205], 13a [blocks 1305, 1306, 1307, 
1308], 13b [blocks 1309, 1310, 1311]; column 4, lines 12-18; column 4, lines 31-62; column 5, 
lines 1-40; column 5, line 41 to column 6, line 13); and 

output means for outputting an output digital signal representing an evaluation result 
(Figures 6 [blocks 613, 614], 7 [blocks 705, 706], 8 [blocks 805, 806], 9 [blocks 906, 907], 10a 



Application/Control Number: 09/463,907 Page 6 

Art Unit: 2131 

[blocks 1015, 1016, 1017, 1018], 10b [blocks 1031, 1032, 1033, 1034], 11 [blocks 1106, 1107], 
12 [blocks 1206, 1207], 13b [block 1312] ; column 4, lines 12-18; column 4, lines 31-62; column 

5, lines 1-40; column 5, line 41 to column 6, line 13). 

16. Kim discloses the use of differential and linear cryptanalysis, which includes predicting 
the probability of a successful attack. This is discussed in depth in Block Cipher - Analysis, 
Design and Application, by Lars Knudsen, hereinafter referred to as Knudsen, in at least 
Sections 5.2 [DifTerential Cryptanalysis] and 5.3 [Linear Cryptanalysis, as well as Section 

6. L6 [Linear Cryptanalysis], specifically equation 6.2. Kim discloses a similar equation to that 
of equation 6.2 in column 4, lines 25-30. Thus the equation ^(Dx, Qy) = |2x#{x 8 GF(2)"|(S(x) 
+ S(x + Dx)) • Dy = 1 } - 2"|, is a part of differential-linear analysis as it appears to be a 
differentiated version of equation 6.2 of Knudsen. Therefore the s-box is evaluated with respect 
to E, where H is the probability of a successful attack being executed during the cryptanalysis 
routine. 

17. Kim discloses using linear and differential cryptanalysis techniques. Kim does not 
disclose wherein the cryptanalysis method is differential-linear cryptanalysis. 

18. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use differential-linear cryptanalysis, since Langford states on pages 17 and 18 that 
such a modification reduces the amount of text required in the analytic attacks. Therefore, 
Langford discloses counting all sets of input difference value Dx and output mask value Dy of 
each of the functions S(x) read out of the storage means, a number of inputs values x for which 
the inner product of (S(x)+S(x + Dx)) and said output mask value Dy is 1, as illustrated by 
Figure 2, on page 21 and is discussed in Section 5, Structures on pages 23 and 24 . Kim 
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provides further motivation for the judging the resistance of differential-linear cryptanalysis, as 
Kim already discloses methods forjudging criteria against differential and linear cryptanalysis. 
Kim states at column 1, lines 34-43 that such analyses improve the security of DES. 

19. With regards to claims 3, 11, 16, 23, and 29, Kim teaches discloses evaluating 
diflferential-cryptanalysis resistance. Markov Ciphers and Differential Cryptanalysis, by 
Xuejia Lai, discloses that calculating means, for the function S(x) to be evaluated, the number of 
inputs X that satisfy S(x) + S(x + Dx ) = Dy for every set (Dx, Dy) and evaluating the resistance 
of said function to differential cryptanalysis based on the result of said calculation is part of 
differential cryptanalysis in at least Section 2. Differential Cryptanalysis of Iterated Ciphers, 
on pages 19-22. 

20. Kim discloses linear-cryptanalysis resistance evaluating means for calculating, for the 
function to be evaluated, the number of input values x for which the inner product of the input 
value X and its mask value Dx is equal to the inner product of a function output value S(x) and its 
mask value Dy and evaluating the resistance of said function to linear cryptanalysis based on the 
result of said calculation (Figures 7-9; column 4, lines 19-62). 

21. Claims 8, 13, 14-16, 18-23, 25, 26, and 31-38 are rejected under 35 U.S. C. 103(a) as 
being unpatentable over Kim in view of The Interpolation Attack on Block Ciphers, by 
Thomas Jakobsen et al, hereinafter Jakobsen, as applied to claim 6 above, and further in view of 
Partitioning Cryptanalysis, by Carlo Harpes, hereinafter Harpes, in view of Langford. 
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22. Regarding claim 8, Kim discloses evaluating the resistance of said function to 
cryptanalysis based on the result of said number (Figures 6 [blocks 606, 607], 7 [block 704], 8 
[block 804], 9 [blocks 904, 905], 10a [blocks 1007, 1008, 1009, 1010, 1011, 1012, 1013, 1014], 
10b [blocks 1023, 1024, 1025, 1026, 1027, 1028, 1029, 1030], 11 [block 1105], 12 [blocks 
1205], 13a [blocks 1305, 1306, 1307, 1308], 13b [blocks 1309, 1310, 1311]; column 4, lines 12- 
18; column 4, lines 31-62; column 5, lines 1-40; column 5, line 41 to column 6, line 13); 

23. Wherein said candidate functions are each a composite function composed of at least one 
function resistant to said differential cryptanalysis and said linear cryptanalysis and at least one 
function of an algebraic structure different from that of said at least one function (Figures 6 
[blocks 606, 607], 7 [block 704], 8 [block 804], 9 [blocks 904, 905], 10a [blocks 1007, 1008, 
1009, 1010, 1011, 1012, 1013, 1014], 10b [blocks 1023, 1024, 1025, 1026, 1027, 1028, 1029, 
1030], 11 [block 1105], 12 [blocks 1205], 13a [blocks 1305, 1306, 1307, 1308], 13b [blocks 
1309, 1310, 1311]; column 4, lines 12-18; column 4, lines 31-62; column 5, lines 1-40; column 
5, line 41 to column 6, line 13). 

24. Kim does not disclose using higher-order-differential cryptanalysis, interpolation- 
cryptanalysis, partitioning-cryptanalysis, and differential-linear cryptanalysis. 

25. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use higher-order-differential cryptanalysis, since Jakbbsen states in the Abstract the 
that such a modification would be useful in detecting vulnerabilities of ciphers in low non-linear 
order. Therefore Jakobsen discloses calculating a minimum value of the degree of a Boolean 
polynomial for input bits by which output bits of each of said candidate functions are expressed, 
as discussed in Section 2: Attacks Using Higher Order Differentials. 
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26. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use interpolation-cryptanalysis, since Jakobsen states in the Abstract that such a 
modification would be useful in detecting vulnerabilities in ciphers that use simple algebraic 
functions. Therefore Jakobsen discloses expressing an output value y as y = fk(x) for an input 
value X and a fixed key k using a polynomial over a Galois field which is composed of elements 
equal to a prime p or a power of said prime p and counting a number of terms of said polynomial 
in at least Section 3: The Interpolation Attack. 

27. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use partitioning cryptanalysis, since Harpes states in the Abstract that such a 
modification would exploit a potential weakness of the cipher, namely that the last-round inputs 
are non-uniformly distributed over the blocks of the second partition when the plaintexts are 
taken from a particular block of the first partition. Therefore Harpes discloses dividing all input 
values of the function to be evaluated and the corresponding output values into input subsets and 
output subsets and calculating an imbalance of the relationships between the input subset and the 
output subset with respect to their average corresponding relationship on at least pages 7 and 8, 
in addition to Sections 3-5, on page 9-23. 

28. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use differential-linear cryptanalysis, since Langford states on pages 17 and 18 that 
such a modification reduces the amount of text required in the analytic attacks. Therefore, 
Langford discloses counting all sets of input difference value Dx and output mask value Dy of 
each of the functions S(x) read out of the storage means, a number of inputs values x for which 
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the inner product of (S(x)+S(x + Dx)) and said output mask value Dy is 1, as illustrated by 
Figure 2, on page 21 and is discussed in Section 5, Structures on pages 23 and 24 . 

29. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to include four cryptanalysis routines in one device, since it has been held that forming 
in one piece routines or techniques that were formerly found separately involves only routine 
skill in the art. See MPEP § 2144.04; see Howard v, Detroit Stove Works, 1 50 U.S. 164 (1993); 
see In re Larson, 340 F.2d 965, 967, 144 USPQ 347, 349 (CCPA 1965); see In re Wolfe, 25 1 
F.2d 854, 855, 116 USPQ 443, 444 (CCPA 1958). 

30. As per claims 13 and 20, Kim teaches a random function generating method comprising 
the steps of 

(o) inputting digital signals representing input difference values Dx, output mask values 
□y and parameter values of each of a plurality of functions of different algebraic structures and 
storing them in storage means (Figures 6 [blocks 602, 603, 604], 7 [blocks 702, 703], 8 [blocks 
802, 803], 9 [blocks 902, 903], 10a [blocks 1002, 1003, 1004, 1005, 1006], 10b [blocks 1019, 
1020, 1021, 1022], 11 [block 1102, 1103], 12 [block 1202, 1203]; column 1, lines 35-42; column 
4, lines 1-9; column 4, lines 12-28; column 4, lines 41-63); 

(a) setting various input values read out of the storage means for each of candidate 
functions S(x) of S-box and calculating output values corresponding to said various input values 
X (Figures 6 [blocks 602, 603, 604], 7 [blocks 702, 703], 8 [blocks 802, 803], 9 [blocks 902, 
903], 10a [blocks 1002, 1003, 1004, 1005, 1006], 10b [blocks 1019, 1020, 1021, 1022], 11 
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[block 1 102, 1 103], 12 [block 1202, 1203]; column 1, lines 35-42; column 4, lines 1-9; column 
4, lines 12-28; column 4, lines 41-63); 

(b) storing the output values in storage means (Figures 6 [blocks 606, 607], 7 [block 704], 
8 [block 804], 9 [blocks 904, 905], 10a [blocks 1007, 1008, 1009, 1010, 1011, 1012, 1013', 
1014], 10b [blocks 1023, 1024, 1025, 1026, 1027, 1028, 1029, 1030], 11 [block 1105], 12 
[blocks 1205], 13a [blocks 1305, 1306, 1307, 1308], 13b [blocks 1309, 1310, 131 1]; column 4, 
lines 12-18; column 4, lines 31-62; column 5, lines 1-40; column 5, line 41 to column 6, line 13); 
and 

(c) evaluating the resistance of each of said candidate functions to a cryptanalysis based 
on values stored in said storage means, and selectively outputting candidate function highly 
resistant to said cryptanalysis (Figures 6 [blocks 606, 607], 7 [block 704], 8 [block 804], 9 
[blocks 904, 905], 10a [blocks 1007, 1008, 1009, 1010, 1011, 1012, 1013, 1014], 10b [blocks 
1023, 1024, 1025, 1026, 1027, 1028, 1029, 1030], 11 [block 1105], 12 [blocks 1205], 13a 
[blocks 1305, 1306, 1307, 1308], 13b [blocks 1309, 1310, 1311]; column 4, lines 12-18; column 
4, lines 31-62; column 5, lines 1-40; column 5, line 41 to column 6, line 13); and 

3 1 . Kim does not disclose using higher-order-differential cryptanalysis, interpolation- 
cryptanalysis, partitioning-cryptanalysis, and differential-linear cryptanalysis. 

32. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use higher-order-diflferential cryptanalysis, since Jakobsen states in the Abstract the 
that such a modification would be useful in detecting vulnerabilities of ciphers in low non-linear 
order. Therefore Jakobsen discloses calculating a minimum value of the degree of a Boolean 
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polynomial for input bits by which output bits of each of said candidate functions are expressed, 
as discussed in Section 2: Attacks Using Higher Order Differentials. 

33. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use interpolation-cryptanalysis, since Jakobsen states in the Abstract that such a 
modification would be useful in detecting vulnerabilities in ciphers that use simple algebraic 
functions. Therefore Jakobsen discloses expressing an output value y as y = fk(x) for an input 
value X and a fixed key k using a polynomial over a Galois field which is composed of elements 
equal to a prime p or a power of said prime p and counting a number of terms of said polynomial 
in at least Section 3: The Interpolation Attack. 

34. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use partitioning cryptanalysis, since Harpes states in the Abstract that such a 
modification would exploit a potential weakness of the cipher, namely that the last-round inputs 
are non-uniformly distributed over the blocks of the second partition when the plaintexts are 
taken from a particular block of the first partition. Therefore Harpes discloses dividing all input 
values of the function to be evaluated and the corresponding output values into input subsets and 
output subsets and calculating an imbalance of the relationships between the input subset and the 
output subset with respect to their average corresponding relationship on at least pages 7 and 8, 
in addition to Sections 3-5, on page 9-23. 

35. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use differential-linear cryptanalysis, since Langford states on pages 17 and 18 that 
such a modification reduces the amount of text required in the analytic attacks. Therefore, 
Langford discloses counting all sets of input difference value Dx and output mask value Oy of 
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each of the functions S(x) read out of the storage means, a number of inputs values x for which 
the inner product of (S(x)+S(x + Dx)) and said output mask value Dy is 1, as illustrated by 
Figure 2, on page 21 and is discussed in Section 5, Structures on pages 23 and 24 . 

36. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to include four cryptanalysis routines in one device, since it has been held that forming 
in one piece routines or techniques that were formerly found separately involves only routine 
skill in the art. See MPEP § 2144.04; see Howard v. Detroit Stove Works, 150 U.S. 164 (1993); 
see In re Larson, 340 F.2d 965, 967, 144 USPQ 347, 349 (CCPA 1965); see In re Wolfe, 251 
F.2d 854, 855, 116 USPQ 443, 444 (CCPA 1958). 

37. Regarding claims 14 and 21, Kim discloses the use of differential and linear 
cryptanalysis, which includes predicting the probability of a successful attack. This is discussed 
in depth in Block Cipher - Analysis, Design and Application, by Lars Knudsen, hereinafter 
referred to as Knudsen, in at least Sections 5.2 [Differential Cryptanalysis] and 5.3 [Linear 
Cryptanalysis, as well as Section 6.L6 [Linear Cryptanalysis], specifically equation 6.2. Kim 
discloses a similar equation to that of equation 6.2 in column 4, lines 25-30. Thus the equation 
^s(Dx, Dy) = |2x#{x e GF(2)"|(S(x) + S(x + Dx)) • Dy = 1 } ^ 2"|, is a part of differential-linear 
analysis as it appears to be a differentiated version of equation 6.2 of Knudsen, Therefore the s- 
box is evaluated with respect to H, where S is the probability of a successful attack being 
executed during the cryptanalysis routine. 

38. Harpes discusses the principles behind a partitioning cryptanalysis attack on pages 7 and 
8 and the probability of success of partitioning cryptanalysis, including imbalance, on pages 11- 
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23. Therefore Harpes discloses the step of dividing an input value set F and an output value set 
G of said function into u input subsets {FO, Fl,...,Fu-l} and v output subsets {GO, Gl,...,Gv-l, 
for each partition pair (Fi, Gi) (i = 0,...., u-1; j = 0,...,v-l), calculating a maximum one of 
probabilities that all output values y corresponding to all input values x of the input subset Fi 
belong to the respective output subsets Gj (j = 0,. v-1), and calculating a measure IS(F,G) of 
an average imbalance of a partition-pair (F,G) based on all maximum values calculated for all 
partition pairs. 

39. Kim discloses evaluating the resistance of said candidate function to said cryptanalysis 
based on said measure (Figures 6 [blocks 606, 607], 7 [block 704], 8 [block 804], 9 [blocks 904, 
905], 10a [blocks 1007, 1008, 1009, 10.10, 1011, 1012, 1013, 1014], 10b [blocks 1023, 1024, 
1025, 1026, 1027, 1028, 1029, 1030], 11 [block 1105], 12 [blocks 1205], 13a [blocks 1305, 1306, 
1307, 1308], 13b [blocks 1309, 1310, 1311]; column 4, lines 12-18; column 4, lines 31-62; 
column 5, lines 1-40; column 5, line 41 to column 6, line 13). 

40. Regarding claims 15, 18, 22, and 25, Kim discloses setting aside candidate functions that 
fail the testing conditions. It would have been obvious to one of ordinary skill in the art at the 
time the invention was made to ease the candidate function selection condition by changing said 
reference by a predetermined width and executing the evaluation process and selecting process 
again, since it has been determined that the invention is designed to find the most suitable s-box 
design. It would have only required routine skill in the art to repeat the process for every 
cryptanalysis technique. See MPEP § 2144.04; see In re Harza, 274 F.2d 669, 671, 124 USPQ 
378,380 (CCPA 1960). 



Application/Control Number: 09/463,907 
Art Unit: 2131 



Page 15 



41 . Regarding claims 19, 26, 3 1, and 32, Kim teaches wherein said candidate functions are 
each a composite function composed of at least one function resistant to said differential 
cryptanalysis and said linear cryptanalysis and at least one function of an algebraic structure 
different from that of said at least one function (column 4, lines 12-62). 

42. Regarding claims 33,35, and 37, Kim does not disclose using higher-order-diflferential 
cryptanalysis, interpolation-cryptanalysis, partitioning-cryptanalysis, and differential-linear 
cryptanalysis. 

43. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use higher-order-differential cryptanalysis, since Jakobsen states in the Abstract the 
that such a modification would be useful in detecting vulnerabilities of ciphers in low non-linear 
order. Therefore Jakobsen discloses calculating a minimum value of the degree of a Boolean 
polynomial for input bits by which output bits of each of said candidate functions are expressed, 
as discussed in Section 2: Attacks Using Higher Order Differentials. 

44. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use interpolation-cryptanalysis, since Jakobsen states in the Abstract that such a 
modification would be useful in detecting vulnerabilities in ciphers that use simple algebraic 
functions. Therefore Jakobsen discloses expressing an output value y as y = fk(x) for an input 
value X and a fixed key k using a polynomial over a Galois field which is composed of elements 
equal to a prime p or a power of said prime p and counting a number of terms of said polynomial 
in at least Section 3: The Interpolation Attack. 
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45. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use partitioning cryptanalysis, since Harpes states in the Abstract that such a 
modification would exploit a potential weakness of the cipher, namely that the last-round inputs 
are non-uniformly distributed over the blocks of the second partition when the plaintexts are 
taken from a particular block of the first partition. Therefore Harpes discloses dividing all input 
values of the function to be evaluated and the corresponding output values into input subsets and 
output subsets and calculating an imbalance of the relationships between the input subset and the 
output subset with respect to their average corresponding relationship on at least pages 7 and 8, 
in addition to Sections 3-5, on page 9-23. 

46. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use differential-linear cryptanalysis, since Langford states on pages 17 and 18 that 
such a modification reduces the amount of text required in the analytic attacks. Therefore, 
Langford discloses counting all sets of input difference value Dx and output mask value Dy of 
each of the functions S(x) read out of the storage means, a number of inputs values x for which 
the inner product of (S(x)+S(x + Dx)) and said output mask value Dy is 1, as illustrated by 
Figure 2, on page 21 and is discussed in Section 5, Structures on pages 23 and 24 . 

47. It would have been obvious to one of ordinary skill in the art at the time the invention 
was made to include four cryptanalysis routines in one device, since it has been held that forming 
in one piece routines or techniques that were formerly found separately involves only routine 
skill in the art. See MPEP § 2144.04; see Howard v. Detroit Stove Works, 150 U.S. 164 (1993); 
see In re Larson, 340 F.2d 965, 967, 144 USPQ 347, 349 (CCPA 1965); see In re Wolfe, 251 
F;2d 854, 855, 1 16 USPQ 443, 444 (CCPA 1958). 



Application/Control Number: 09/463,907 
Art Unit: 2131 



Page 17 



48. With regards to claims 34, 36, and 38, Harpes discusses the principles behind a 
partitioning cryptanalysis attack on pages 7 and 8 and the probability of success of partitioning 
cryptanalysis, including imbalance, on pages 1 1-23. Therefore Harpes discloses the step of 
dividing an input value set F and an output value set G of said function into u input subsets (FO, 
Fl,...,Fu-l} and v output subsets {GO, Gl,.,.,Gv-l, for each partition pair (Fi, Gi) (i = 0,,,.., u- 
1 ; j = 0, . . , ,v- 1), calculating a maximum one of probabilities that all output values y 
corresponding to all input values x of the input subset Fi belong to the respective output subsets 
Gj G = 0, ■ v-1), and calculating a measure IS(F,G) of an average imbalance of a partition-pair 
(F,G) based on all maximum values calculated for all partition pairs, 

49. Kim discloses evaluating the resistance of said candidate function to said cryptanalysis 
based on said measure (Figures 6 [blocks 606, 607], 7 [block 704], 8 [block 804], 9 [blocks 904, 
905], 10a [blocks 1007, 1008, 1009, 1010, 1011, 1012, 1013, 1014], 10b [blocks 1023, 1024, 
1025, 1026, 1027, 1028, 1029, 1030], 11 [block 1105], 12 [blocks 1205], 13a [blocks 1305, 
1306, 1307, 1308], 13b [blocks 1309, 1310, 131 1]; column 4, lines 12-18; column 4, lines 31-62; 
column 5, Hnes 1-40; column 5, line 41 to column 6, line 13). 

Claim Objections 

50. Claim 1 1 is objected to under 37 CFR 1 .75(c) as being in improper form because a 
multiple dependent claim should refer to other claims in the alternative only (i.e. any one of 
claims 9, 35, or 36). See MPEP § 608.01(n). Accordingly, the claim has not been further treated 
on the merits. 
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Conclusion 



5 1 . Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Christian La Forgia whose telephone number is (571) 272-3792. 
The examiner can normally be reached on Monday thru Thursday 7-5. 

52. If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Ayaz Sheikh can be reached on (571) 272-3795. The fax phone number for the 
organization where this application or proceeding is assigned is 703-872-9306. 

53. Information regarding the status of an application may be obtained from the Patent 
Application Information Retrieval (PAIR) system. Status information for published applications 
may be obtained from either Private PAIR or Public PAIR. Status information for unpublished 
applications is available through Private PAIR only. For more information about the PAIR 
system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR 
system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). 

Christian LaForgia 

Patent Examiner , j 
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